Facial recognition adversarial patch adjustment is performed by applying a patch to a digital image including image data representing a face to obtain a patched image, applying a face detector to the patched image to obtain a detection value representing a likelihood that the patched image includes image data representing facial features, applying a feature extractor to the patched image to obtain a feature vector, applying a similarity determiner to the feature vector and a target feature vector to obtain a similarity value representing a likelihood that the patched image includes image data representing a target face, calculating a loss based on the detection value and the similarity value, and adjusting the patch based on the loss.
Legal claims defining the scope of protection, as filed with the USPTO.
2. The non-transitory computer-readable medium of claim 1, wherein the loss is based on an additive inverse of the similarity value.
3. The non-transitory computer-readable medium of claim 1, wherein calculating the loss includes multiplying one of the detection loss and the similarity value by a weighting factor.
5. The non-transitory computer-readable medium of claim 1, wherein the adjusting the patch includes adjusting a color of each pixel of the patch according to a gradient based on the loss.
6. The non-transitory computer-readable medium of claim 5, wherein the applying the patch includes replacing image data of a partial area of the sample image with image data of the patch.
11. The method of claim 10, wherein calculating the loss includes multiplying one of the detection loss and the similarity value by a weighting factor.
12. The method of claim 10, wherein the adjusting the patch includes adjusting a color of each pixel of the patch according to a gradient based on the loss.
16. The apparatus of claim 15, wherein calculating the loss includes multiplying one of the detection loss and the similarity value by a weighting factor.
17. The apparatus of claim 15, wherein the adjusting the patch includes adjusting a color of each pixel of the patch according to a gradient based on the loss.
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
November 25, 2021
December 31, 2024
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.